Typical severity: High. Likelihood of attack: Medium. An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.
Create a strong password policy and ensure that your system enforces this policy for Kerberos service accounts. | Ensure Kerberos service accounts are not reusing username/password combinations for multiple systems, applications, or services. | Do not reuse Kerberos service account credentials across systems. | Deny remote use of Kerberos service account credentials to log into domain systems. | Do not allow Kerberos service accounts to be a local administrator on more than one system.